> ## Documentation Index
> Fetch the complete documentation index at: https://docs.propal.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Attach a proposal product

> Attaches an existing proposal_products row (NOT a bundle) to the proposal. Idempotent — replaces any existing attachment.



## OpenAPI

````yaml /openapi.json put /v1/proposals/{id}/product
openapi: 3.1.0
info:
  title: Propal Public API
  version: 1.0.0
  description: >-
    Public REST API for Propal — proposals, leads, catalog, templates, themes,
    media, metrics, and organization. An MCP (Model Context Protocol) endpoint
    is also available at `POST /v1/mcp` for AI agents — it requires the
    `mcp:use` scope and exposes the same resources as tools, plus prefab section
    templates to compose proposals.
servers:
  - url: https://api.propal.io
    description: Production
security: []
paths:
  /v1/proposals/{id}/product:
    put:
      tags:
        - Proposals
      summary: Attach a proposal product
      description: >-
        Attaches an existing proposal_products row (NOT a bundle) to the
        proposal. Idempotent — replaces any existing attachment.
      parameters:
        - schema:
            type: string
            format: uuid
            description: Proposal UUID
          required: true
          name: id
          in: path
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                proposal_product_id:
                  type: string
                  format: uuid
              required:
                - proposal_product_id
      responses:
        '204':
          description: Proposal product attached
        '400':
          description: Validation error
        '401':
          description: Unauthorized — missing or invalid API key
        '403':
          description: Forbidden — API key missing required scope
        '404':
          description: Resource not found
        '429':
          description: Rate limit exceeded
      security:
        - BearerAuth: []
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: 'API key in format: pp_live_xxxxxxxxxxxxxxxxxxxxxxxx'

````